CVE-2026-62221
Last modified
CVE-2026-62221 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | >= 2026.5.12, < 2026.5.26 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-62221?
How severe is CVE-2026-62221?
How do I fix CVE-2026-62221?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62216OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass …5
- CVE-2026-62217OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an author…8.8
- CVE-2026-62218OpenClaw 2026.1.20 before 2026.5.27 contain an authorization…8.8
- CVE-2026-62219OpenClaw 2026.2.12 before 2026.5.26 contain an authorization…7.1
- CVE-2026-6222The Forminator Forms plugin for WordPress is vulnerable to M…5.3
- CVE-2026-62220OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust call…6.3
- CVE-2026-62222OpenClaw before 2026.5.22 contain a vulnerability in setup-m…7.8
- CVE-2026-62223OpenClaw before 2026.5.18 contain an authorization bypass vu…8.8
- CVE-2026-62224OpenClaw MS Teams before 2026.5.12 contain an authorization …5.4
- CVE-2026-62225OpenClaw versions before 2026.5.18 contain an authorization …5.4
- CVE-2026-62226OpenClaw 2026.3.28 before 2026.5.19 contain an authorization…8.5
- CVE-2026-62227OpenClaw 2026.4.14 before 2026.5.26 contain a server-side re…7.7
Are you affected by CVE-2026-62221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
